Description
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
Published: 2026-09-05
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A security flaw in the Tenda CP3 firmware (27.5.57.101) allows an attacker to remotely inject operating‑system commands by manipulating the AlarmVoiceURL argument in the SystemAsh function within Apis/system.c. This injection can execute arbitrary commands with the privileges of the device, leading to full system compromise, data exfiltration, or disruption of network services.

Affected Systems

The vulnerable vendor is Tenda, specifically the CP3 router series. The flaw exists in firmware version 27.5.57.101; it is not confirmed whether other firmware builds of the CP3 are affected.

Risk and Exploitability

The CVSS score of 9.4 marks this as a critical vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, so current exploitation evidence is unknown. The flaw is exploitable remotely through the device’s API, implying that an attacker who can reach the router could gain full control. The lack of public exploit data does not diminish the inherent risk posed by the high severity and remote attack vector.

Generated by OpenCVE AI on September 5, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Tenda CP3 to the latest firmware that addresses the SystemAsh command‑injection issue.
  • If a firmware update is not yet available, disable or restrict the remote management interface that uses the AlarmVoiceURL parameter, or apply an ACL to limit access to trusted internal IPs.
  • Configure firewall rules to block external traffic to the device’s management ports, thereby preventing remote exploitation of the vulnerable endpoint.

Generated by OpenCVE AI on September 5, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda cp3
Vendors & Products Tenda cp3

Sat, 05 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
Title Tenda CP3 Kylin system.c SystemAsh os command injection
First Time appeared Tenda
Tenda cp3 Firmware
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:o:tenda:cp3_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda cp3 Firmware
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-05T21:45:09.573Z

Reserved: 2026-09-05T07:40:03.572Z

Link: CVE-2026-86148

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T22:17:18.743

Modified: 2026-09-05T22:17:18.743

Link: CVE-2026-86148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T00:00:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')